隐私说明
更新于 2026-10-09 · 适用于 dropit 网页收件箱、浏览器扩展、Obsidian 插件、命令行和 iPhone 快捷指令
dropit 只做一件事:把你在一台设备上投递的东西,送到你的其他设备上。为了送到,我们要在服务器上暂存你投递的内容,到期就删。我们不卖数据、不放广告、不做统计分析,也不看、不分析你投递的内容。
我们存了什么
- 账号:一个随机生成的编号。免费账号没有姓名、邮箱或手机号。
- 付费后:你在付款页填的邮箱、付款服务商 Creem 给的客户编号和订阅编号、每一笔订单的套餐、金额、日期和状态(已付 / 已退款),以及激活码的摘要(SHA-256,不存激活码本身)。卡号等支付信息只在 Creem,我们收不到。
- 设备:每台设备的名称(客户端自己起的,比如「浏览器 · MacIntel」「CLI · 你的主机名」「Obsidian」「iPhone · 快捷指令」)、权限(完整 / 只能投递)、最近一次活动的时间(最多每小时更新一次)、这台设备钥匙的摘要(SHA-256),以及一个设备指纹的摘要(见下方「设备指纹」)。
- 你投递的内容:你主动发出的文字、链接和文件(含文件名和类型);如果是从网页投递的,还有那个网页的标题、简介和地址;以及投递时间、从哪个客户端发出。
- 用量:今天投了几条、占了多少空间,用来执行套餐的上限。
- 网络地址:我们不保存 IP 地址本身,只保存它不可还原的摘要(IPv6 按 /64 网段算),用来限制同一网络每天建号的个数和输错配对码的次数,第二天就清掉。
- 运行统计:每次请求的结果(成功还是被拒、哪个接口、用了多久),不带账号或设备编号,用来发现故障和滥用。
设备指纹
加入或配对时,客户端会在你的设备上把几项不常变的信息(Obsidian 是一个随机 ID)算成一个 SHA-256 摘要,只发送摘要,不发送这些信息本身。它只有一个用途:你重装客户端、清了浏览器数据之后再加入时,认出这是同一台设备上的同一个客户端,替换掉旧的那台,而不是多占一个设备名额。它不是登录凭证,也不用于任何追踪。
存多久
谁能看到
- 你的设备:同一个账号里有完整权限的设备能收到你投递的内容。付款邮箱只以打码的形式(如 pe•••@gmail.com)显示在你的设备上。只能投递的设备(用配对码加入的浏览器扩展、iPhone 快捷指令)读不到。在扩展里创建账号的那个浏览器拿的是完整权限,用来把你的其他设备加进来。
- 服务提供商:dropit 运行在 Cloudflare 上(程序运行、数据库、文件存储、防刷的人机验证)。人机验证只在同一网络当天建号较多时才出现。付款由 Creem 处理(交易的记录商户):你在付款页填的邮箱和支付信息由 Creem 收集,适用 Creem 的隐私政策;它把邮箱和订单信息发给我们,用来开通付费版。除此之外不使用任何第三方服务:网页没有第三方统计、广告或字体。
- 我们:内容传输时用 HTTPS 加密,存储时由服务商用 AES-256 加密。这不是端到端加密:解密的钥匙在服务这边,所以技术上我们能读到。我们不会查看、分析或把它用于投递以外的任何用途,内容到期即删除。密码、证件这类特别敏感的东西,建议不要用 dropit 传。
- 我们不出售、不出租、不共享你的数据给任何人用于广告或分析。
在你设备上存的东西
每台设备的钥匙只存在那台设备上:命令行在 ~/.config/dropit/config.json,扩展在浏览器的扩展本地存储,Obsidian 在插件的 data.json,网页收件箱在浏览器的本地存储(同时缓存收到的内容)。浏览器扩展只在你点投递时读取当前网页的标题、简介、地址和你选中的文字,不读取浏览记录。
你能做什么
变更
收集的内容、保存的时长或服务提供商有变化时,会更新这一页并改上面的日期。客户端改变收集方式时也会在界面上说明。
Privacy
Updated 2026-10-09 · Covers the dropit web inbox, browser extension, Obsidian plugin, command line and iPhone Shortcuts
dropit does one thing: it gets what you send from one device to your other devices.
To do that it keeps what you send on our server for a short while, and deletes it when that time is up.
We don't sell data, show ads or run analytics, and we don't look at or analyze what you send.
What we keep
- Account: a randomly generated ID. A free account has no name, email address or phone number.
- Once you pay: the email you enter at checkout, the customer and subscription IDs from our payment provider Creem, each order's plan, amount, date and status (paid / refunded), and a hash of the activation code (SHA-256; the code itself isn't kept). Card details stay with Creem; we never receive them.
- Devices: each device's name (chosen by the client, such as "Browser · MacIntel", "CLI · your host name", "Obsidian",
"iPhone · Shortcut"), its access (full or send-only), when it was last active (updated at most hourly), a SHA-256 hash of its key,
and a hash of its device fingerprint (see "Device fingerprint" below).
- What you send: the text, links and files you choose to send (with file names and types); when sent from a web page,
that page's title, description and address; and when it was sent and from which client.
- Usage: how many items you sent today and how much space they take, to apply your plan's limits.
- Network address: we don't keep your IP address itself, only a one-way hash of it (per /64 for IPv6),
used to limit how many accounts one network creates and how many wrong pairing codes it tries in a day. It's cleared the next day.
- Service statistics: the outcome of each request (succeeded or refused, which endpoint, how long it took), without any account or device ID, to spot failures and abuse.
Device fingerprint
When joining or pairing, the client turns a few facts that rarely change (for Obsidian, a random ID) into a SHA-256 hash on your device and
sends only the hash, never the facts. It has one purpose: when you join again after reinstalling or clearing browser data,
the service recognizes the same client on the same device and lets the new join take the old one's place instead of using another device slot.
It is not a credential and is not used for tracking.
How long
Who can see it
- Your devices: devices with full access on your account receive what you send. Your payment email appears on your devices only masked (like pe•••@gmail.com). Send-only devices (a browser extension joined with a pairing code, the iPhone shortcut) can't read it. The browser where you create an account in the extension holds a full-access key, so it can add your other devices.
- Service provider: dropit runs on Cloudflare (running the service, database, file storage, and a human check against abuse).
The human check only appears when one network has created several accounts that day. Payments are handled by Creem (the Merchant of Record for the sale):
the email and payment details you enter at checkout are collected by Creem under Creem's privacy policy; it sends us the email and order details to turn Paid on.
No other third-party services: the web inbox has no third-party analytics, ads or fonts.
- Us: content is encrypted in transit (HTTPS) and encrypted at rest by our provider (AES-256). This is not end-to-end encryption: the keys are on the service side, so technically we could read it.
We don't look at it, analyze it or use it for anything but delivering it, and it is deleted when it expires. For especially sensitive things such as passwords or ID documents, we suggest not sending them through dropit.
- We don't sell, rent or share your data with anyone for advertising or analytics.
What stays on your devices
Each device's key stays on that device: the command line in ~/.config/dropit/config.json, the extension in the browser's local extension storage,
Obsidian in the plugin's data.json, the web inbox in the browser's local storage (which also caches what you've received).
The browser extension reads the current page's title, description, address and your selected text only when you send; it doesn't read your browsing history.
What you can do
- Remove other devices from any device with full access (web inbox → Devices, Obsidian settings,
dropit revoke).
- Signing out of the extension, unpairing in Obsidian and signing out of the web inbox each remove that device from your account.
- Items are deleted automatically when they expire. To delete your whole account and everything in it right away, contact us: privacy@smart-kits.xyz. For anything else (your account, using dropit), write to support@dropit.smart-kits.xyz.
Changes
When what we collect, how long we keep it or our service provider changes, this page is updated along with the date above. Clients say so in their interface too when how they collect changes.